Overpass-the-Hash via RC4 Kerberos Pre-Authentication

Detects Kerberos TGT requests (Event ID 4768) that utilize RC4 (PreAuthType 23) for pre-authentication. This is a common indicator of an Overpass-the-Hash attack, where an adversary uses a stolen NTLM hash to authenticate as a user and request a Kerberos ticket in environments that are typically configured for AES encryption.